Technical documentation

Data Protection and Privacy

MATCHA Writer is a local-first desktop application. When used unlicensed (free edition) outside of a course context, it does not share any information with us, MATCHA Technologies Ltd., or anyone else. This is the starting point for privacy and security in MATCHA: no shared information .

The rest of this page explains when and how MATCHA departs from this starting point. For more general information about how we collect and use information throughout our business, including the portal tools available to instructors and administrators, see our general Privacy Policy .

Course participation and privacy levels

When a student is writing in MATCHA for a course activity, we need to keep track of some activity metadata to enforce academic integrity constraints. However, MATCHA is able to operate with very little information sharing. The level of information sharing can be controlled by setting the Privacy Level setting at the organization level or course level. Organization-level settings constrain course settings, which constrain activity settings. The following privacy levels are available:

Level 1 Standard

MATCHA Writer may share students' personally identifiable information as well as students' work histories with MATCHA and subprocessors (depending on the activity features used). See Data Sharing by Activity Features for more information. As described below, information shared is clearly stated to students as part of a pre-activity information collection disclosure.

Level 2 No personally identifiable information (PII) shared

MATCHA Writer encrypts all personally identifiable information .

  • What is not shared with us: Personally identifiable information is encrypted end-to-end between the student's copy of MATCHA Writer and the instructor's.
  • What is still shared with us: MATCHA Writer still shares anonymous control data for troubleshooting and integrity enforcement purposes. It may also share anonymized student works in readable form if the AI assistant is used or follow-up quizzes are used with AI assistance.
  • Incompatible features: Live Collaboration, Cloud Sync
  • Other limitations: A course passcode known only to course staff needs to be used to access student submissions and activity control metadata. We cannot recover lost passcodes or decrypt submissions.

Level 3 No student personal information (PI) shared

A notch more private than Level 2, this mode prevents any student personal information from being shared.

  • What is not shared with us: Personal information of any sort, including students' work-products, are always encrypted end-to-end.
  • What is still shared with us: Control data .
  • Incompatible features: Like Level 2, plus: AI assistance, student-specific questions for follow-up quizzes, AI assessment for follow-up quizzes.
  • Other limitations: Like Level 2.

Level 4 Zero trust

The ultimate privacy-protecting mode, this mode is designed so you and your students don't have to trust MATCHA services or your installed copy of MATCHA Writer with more information than is strictly necessary for MATCHA to do its basic job.

  • What is protected: Everything in Level 3, plus students are not allowed to browse web resources in the built-in browser (so there is no need to trust MATCHA Writer with any confidential information students might use when browsing, such as login credentials for your university's library). MATCHA Writer still asks students for name and ID to attach this information to submissions, encrypted end-to-end, but pseudonyms or incomplete information can be used if desired.
  • What is still shared: Control data .
  • Incompatible features: Like Level 3, plus normal browsing (outside course packs).

Importantly, usage of individual licenses and technical support imply exceptions to these data sharing rules, as described below. Beyond Zero Trust, another option is to not use instructor-managed activities. An instructor can ask her students to create independent MATCHA projects with certain settings (including Complete Work History). The produced .mcha or .docx files can be uploaded to the LMS, and the instructor can verify that the required settings were in place. In this local mode, Writer does not even share control data with us.

Licensing

When licensed by an individual, MATCHA Writer shares basic billing and account information with us and our payment processor, Stripe, which handles sensitive payment information.

Note for teaching institutions: Students do not need to have individual licenses to use MATCHA for their courses unless your institution has selected the student pay licensing model .

Individual use of Cloud Sync and Live Collaboration

Cloud Sync and Live Collaboration are features that store a document's primary copy in MATCHA Cloud so it can be synchronized across devices or shared with collaborators. When enabled, MATCHA may collect:

  • Document content, notes, references, project metadata, and edit history needed to synchronize the project.
  • User, collaborator, permission, presence, and activity metadata needed to show and control shared access.

Note for teaching institutions: These features can be and usually are disabled for course activities as part of our global security controls, discussed above.

Technical support

Making a technical support request requires sharing personal identifiable information (minimally, name and email). This allows us to get back to you about the problem. In addition, we suggest attaching your project file if relevant. Project files contain your editing and browsing history for the project.

How we protect students' privacy

Information collection disclosures

MATCHA clearly discloses the information it collects. Because collection depends on the features enabled for an activity, MATCHA uses two layers of disclosure: a general disclosure in its End User License Agreement and a specific activity disclosure shown before a student starts an instructor-led activity.

The activity-specific disclosure appears in the Activity Summary and emphasizes the information collected for that activity's actual configuration.

Example Activity Summary section showing information collected: name, student identification, editing history, project data, and browsing history.
Figure 1. Example Activity Summary information-collection disclosure detailing what information is shared with who (collected on local computer only, shared with teaching staff, shared with MATCHA and/or subprocessors) .

Just to be sure, we also show this reminder whenever a users starts a new browsing session and Complete Work History (browsing recording) is enabled:

Screenshot of the reminder shown when complete work history is enabled in MATCHA
Figure 2. Reminder shown when Complete Work History is enabled (expanded view).

Security standards

  • Account security: MATCHA requires strong passwords, uses best-practice password hashing techniques, locks accounts after repeated failed sign-in attempts, and requires multi-factor authentication (OTP) for privileged accounts such as administrators and instructors.
  • Encryption in transit: MATCHA services communicate over HTTPS or WebSocket Secure, including service-to-service communications.
  • Encryption at rest: MATCHA-controlled cloud data is protected by provider storage encryption and backup safeguards.
  • End-to-end encryption: When enabled (see above) end-to-end encryption of personal student information guarantees that neither MATCHA nor its subprocessors can access the information even as it transits through our services.
  • Cryptographic standards: MATCHA uses FIPS-aligned, NIST-recommended cryptographic algorithms and modern key-management practices across its services.
  • Standard-compliant infrastructure: MATCHA's hosting facilities are certified SOC 2 Type II and ISO/IEC 27001, 27701, 27017, and 27018.
  • Official Microsoft and Apple distribution channels: MATCHA Writer is distributed as digitally signed installer packages verified malware-free and constrained to low-security runtime profiles by Microsoft and Apple. Installation does not require administrator privileges or granting any special permissions.

GDPR compliance

MATCHA is designed and operated to support GDPR-compliant deployments. In institution-configured courses and activities, MATCHA commonly acts as a processor or service provider while the institution determines the educational purpose, legal basis, notices, retention, and downstream use of records. For MATCHA-controlled services such as the public website, account administration, billing, security monitoring, and support, MATCHA may act as controller.

MATCHA supports privacy requests, deletion requests, access requests, and institution-directed request handling subject to contractual, legal, security, backup, and institutional limits. Questions or privacy requests may be sent to our Data Privacy Officer at dpo@matchatech.io .

Additional data security options available to organizations

In addition to the four privacy levels described above, organizations can also configure the following privacy and security settings.

Metadata residency

Accounts and organizations can be created within one of three geographically isolated MATCHA platforms. Each platform uses separate data-bearing services and storage resources for accounts, organizations, activities, submissions, and documents.

  • MATCHA FedRAMP: A FedRAMP-compliant US regional platform.
  • MATCHA Europe: An EU regional platform fully contained within the EU (including backups).
  • MATCHA Global: The default global platform for organizations that do not require a US or EU regional deployment. Data will often be placed within the user's jurisdiction for performance optimization, but this is not guaranteed.

Submission residency

We offer additional residency options for student submissions (uploaded .docx or .mcha files) on our optional MATCHA Cloud service.

Submissions for FedRAMP and EU-hosted organizations automatically locate within FedRAMP and EU storage buckets. Global-hosted organizations currently have the choice of any of the following locations:

  • Global (unconstrained)
  • Australia
  • Canada East or West
  • India
  • New Zealand
  • Singapore
  • United Kingdom

Data retention

Organizations can configure a course data retention period from 1 to 36 months. The default is 12 months. Courses, activities, submissions, and associated proctoring data are deleted after the course end date plus the configured retention period.

Once data is deleted from active systems, deletion propagates to backup systems as backups rotate. MATCHA's backup retention period is currently 180 days.

Questions?

If you have any questions about MATCHA and data privacy or security, please get in touch with our Data Privacy Officer at dpo@matchatech.io.

We have a HECVAT package with additional documentation for institutional review. Contact dpo@matchatech.io to obtain a copy.